In accordance with the Seller Guide, Sellers have entered a Joint Controller Agreement. This means that both refurbed and Sellers are responsible for how personal data of customers is processed.
As a (joint) data controller, you must be in compliance with data protection law.
The main Regulation on an EU level on the topic of data protection is the GDPR (General Data Protection Regulation). This regulation sets forth a number of Seller obligations including: providing a privacy policy; maintaining records of processing activities; complying with data subject rights (such as deletion requests); ensuring adequate information security; and reporting data breaches.
If there is a data event, such as a data requests or a data leak, which impacts data and/or customers via the refurbed platform, please reach out to your point of contact at refurbed or dataprotection@refurbed.com.
Data breaches are the most common incidents that leads to fines and regulatory action. Examples include, sending a customer the wrong device or sending a device which still has personal data on it.